PRIVACY NOTICE • DRAFT

Privacy should be understandable before you hand over a rental record.

This is a pre-launch draft. It does not claim GDPR certification and must not be treated as final production legal text.

Data-minimisation direction

  • Payment card data stays with Stripe-hosted checkout; STAY does not build a card form.
  • VIEW does not require passport, salary, bank or unrelated identity documents.
  • Property/contact details are collected only where needed to fulfil the selected service.
  • Evidence is user-selected and is designed to be stored privately with tenant-specific access.
  • No non-essential marketing analytics, ad pixels or session recording in the initial release.
  • No real renter case files are sent to ChatGPT for the MVP build or model training.

Planned processors and locations to document

Stripe (payment), Supabase (auth/database/private storage) and Cloudflare (static hosting/DNS) are the planned initial service providers. Their exact contractual/privacy roles and DPAs must be documented before production use.

Access, export and deletion

The product direction includes tenant-specific access and an operator process for export/deletion requests during beta. The exact retention policy and legal exceptions require legal/privacy input before real-evidence production use.

Incident / breach route

LEGAL INPUT REQUIRED: define the controller incident contact and operational breach process before production evidence use.